TechBooky AI Assistant
TechBooky AI Assistant
👋 Welcome to TechBooky AI Assistant

I can help with:
🔎 Tech News
🤖 AI Topics
💻 Gadgets
☁️ Cloud
✍️ Guest Posts
📢 Advertising
🔗 Backlinks
📩 Newsletter
  • AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise Here
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Artificial Intelligence

OpenAI Confirms Hack Linked to TanStack Attack

Akinola Ajibola by Akinola Ajibola
May 14, 2026
in Artificial Intelligence, Security
Share on FacebookShare on Twitter

It has been discovered that hackers took control of multiple open-source projects that were utilised by numerous businesses earlier this week and released updates intended to propagate malware. This is claimed to be the most recent of several recent attacks on software engineers and their projects that are referred to as “supply chain” attacks.

OpenAI acknowledged on Wednesday that this hack had greatly “impacted” the devices of two workers. However, following an inquiry, the business stated in a blog post that it had “no evidence that our production systems or intellectual property were compromised in any way, that our software was altered, or that OpenAI user data was accessed.”

A data breach brought on by a software supply chain attack that has been verified by OpenAI. The popular open-source web application library TanStack was taken over by hackers, which led to the event. OpenAI claims there is no proof that customer user data, production systems, or fundamental AI intellectual property were accessed or compromised, despite the attackers’ successful theft of internal credential material from particular code repositories.

The incident is part of a broader cyber-campaign known as “Mini Shai-Hulud.” This campaign uses compromised developer tools to distribute malware across multiple technology organizations. The attack vector involved pushing 84 malicious package versions to the TanStack library within a six-minute window. 

These packages embedded an information-stealing malware designed to extract local credentials. Two OpenAI employees downloaded the corrupted package onto their devices. As a result, the hackers gained unauthorized access to a limited subset of internal source-code repositories. The attackers exfiltrated limited credentialed data. They also exposed the digital code-signing certificates used to verify OpenAI software.

A prior attack on TanStack, a well-known open-source framework that aids developers in creating web applications, compromised the devices of staff, according to a source from OpenAI.

TanStack had revealed the attack and released a postmortem on Monday, where it claimed that during a six-minute period, hackers released 84 malicious copies of its software. According to the initiative, a researcher found the attack in less than twenty minutes. The malicious TanStack versions contained malware that was intended to self-propagate to spread to other systems and steal login credentials from computers on which the program was installed.

OpenAI claimed that it discovered credentials theft and unauthorized access “in a limited subset of internal source code repositories to which the two impacted employees had access.”

The AI giant claims that “only limited credential material” was extracted from the impacted code repositories. OpenAI stated that it is rotating the digital certificates “as a precaution,” which will require macOS users to update the program, because the impacted repositories held digital certificates used to certify OpenAI’s goods.

The business had stated that they have discovered no evidence of compromise or risk to existing software installations.

The perpetrators of the TanStack attack are unknown. A cyber gang called TeamPCP, which was also a victim of hackers, has been blamed for several of the previous supply chain breaches.

However, similar strategies have been used by other organizations against other initiatives. Axios, a well-known open-source development platform, was taken over by North Korean hackers in March, and they then distributed malware that might have affected millions of developers. Additionally, a similar attack on thousands of Windows systems running Daemon Tools, a disc imaging program, was allegedly carried out by Chinese hackers in May.

Instead of focusing on particular businesses, these attacks include hackers taking over open-source projects and releasing malware under the appearance of harmless routine updates. This enables criminals to spread the harm around the internet by possibly compromising dozens of targets with a single breach. 

Related Posts:

  • vercel-2249343327_f343ad
    Vercel Admits To Customer Data Been Stolen Before…
  • github
    GitHub Confirms Hackers Stole Data From About 3,800…
  • handala hackers
    FBI Warns of Handala Hackers Using Telegram for Malware
  • CISA Releases Nine ICS Advisories (18) (1)
    Palo Alto Networks Data Leak Exposes Customer Details
  • shutterstock_chatgpt
    Researchers Warn ChatGPT Crawler May Cause DDoS…
  • Advantest_rushes_to_boost_AI_chip_tester_Bloomberg_20260128185756_Bloomberg
    Chip Tester Advantest Struck By Ransomware
  • 7-Eleven
    Over 185,000 Affected By 7-Eleven Data Breach
  • ORJAL4DYNFOR3K2HJT2YITAO6Q
    Meta Warns of WhatsApp Security Threat

Discover more from TechBooky

Subscribe to get the latest posts sent to your email.

Tags: hackersopenaiTanStack
Akinola Ajibola

Akinola Ajibola

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • Apple Adds Streaming-Style Subscription Packages To The App Store June 9, 2026
  • Apple Rolls Out Tailored App Store Recommendations June 9, 2026
  • Instagram Rolls Out Custom Profile Grid Arrangement Feature June 9, 2026
  • Signal Argues UK’s Device-Scanning Plan For Nude Images Threatens User Security June 9, 2026
  • UK Regulator Tells Social Media Firms To Stop Viral Illegal Content June 9, 2026
  • Apple Intelligence Gets Major AI Upgrade With New Siri, Safari Tools and Gemini-Powered Models June 9, 2026
  • Gogs Fixes Critical Zero-Day Bug That Enabled Remote Code Execution June 8, 2026
  • Amazon Adds AI-Powered Custom Merch Design June 8, 2026
  • NDPC & Meta Roll Out 2-Year Data Protection Program June 8, 2026
  • FCCPC Deregulates Airtime Lending in Nigeria June 6, 2026
  • Interswitch Jumps Into Africa’s Banking Tech Race With Temenos Deal June 6, 2026
  • Record Labels Face Lawsuit From Musicians’ Union Over AI Licensing June 6, 2026

Browse Archives

June 2026
MTWTFSS
1234567
891011121314
15161718192021
22232425262728
2930 
« May    

Quick Links

  • About TechBooky
  • Advertise Here
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise Here
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.